Article may be outdated

This article is 66 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

Most of the CVE-2026-4020 attackers are the same client

R
Robbedoes
Most of the CVE-2026-4020 attackers are the same client
AI Summary

Security researchers have identified that a massive wave of exploitation targeting a WordPress plugin vulnerability is actually the work of a single coordinated operation. By analyzing HTTP fingerprints, researchers discovered that thousands of rotating IPs and user-agents were masking a single malicious actor.

Why it matters

This highlights the sophistication of modern automated cyberattacks and the limitations of traditional IP-based blocking in defending against large-scale credential harvesting.

Dive DeeperCreate a free account to unlock

Almost every IP we logged exploiting the Gravity SMTP credential bug shares one HTTP fingerprint. Behind it is a Google Cloud fleet of thousands of short-lived instances, disguised by 3,299 rotating user-agents, sweeping more than 36,000 ports for .env files, git configs, credentials, and database dumps.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 95%

The report is a technical analysis of a cybersecurity event based on observable data.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in